Opens in a new tab
vmblog logo 2024 wht (updated)

Axio 2024 Predictions: Quantitative Measurement is Paramount to Navigating Cybersecurity in 2024

Share: 

David Marshall | Published: January 16, 2024

vmblog-predictions-2024 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

Quantitative Measurement is Paramount to Navigating Cybersecurity in 2024

By Richard Caralli, Senior Cybersecurity Advisory, Axio

In 2023, the U.S. economy continued to expand, despite predictions of a recession, a rise in the unemployment rate, and a persistent and stubborn battle with inflation. Commensurately, predictions of a slowdown in consumer and business spending-particularly on “nice-to-have” cybersecurity investments-have not materialized. In fact, the consensus across many cybersecurity market-watchers is that cybersecurity spending in 2024 is on track to increase moderately over steady growth in previous years. Cautions about retracting economic conditions appear to have lost out to the reality that cyber-attacks, in particular ransomware-based attacks, continue to outpace organizational capabilities to prevent them.

However, actions from the Securities and Exchange Commission (SEC) may accelerate cybersecurity investments, further increasing 2024 spending. On December 18, 2023, the SEC’s cybersecurity disclosure rules for publicly traded organizations went into effect, giving many of the largest corporate entities a new incentive to reexamine cybersecurity programs and gap investments. In particular, these investments may need to focus on improving cyber risk and incident management capabilities, and shoring-up internal collaboration on how to determine materiality. And while the SEC’s actions have generated a lot of conversation, 2024 is likely going to be fraught with challenges to the rules, potential adjustments, and a string of follow-on regulations that will continue to exert pressure on organizations to improve their cybersecurity posture.

A few key economic considerations will underscore cybersecurity budgets in 2024. Recent comments by the Chair of the Federal Reserve indicate that inflation is approaching established targets, generating speculation of initial rate cuts occurring in the first quarter of 2024. However, U. S. economic growth is projected by the Congressional Budget Office (CBO) to be slower in 2024 (around 1.5% vs. 2.4% in 2023) and the Federal Reserve Bank of New York predicts a 52% chance that the U. S. will finally experience a long-predicted recession in the next 12 months-precipitating a rise in the unemployment rate to 4.4%. Given the steady growth of cybersecurity spending in 2023 amid predicted challenging economic conditions, it is likely 2024 will follow a similar trajectory.

But the pressure on cybersecurity budgets in 2024 will not necessarily abate. Based on 75 years of market data, presidential election years can have unpredictable effects on economic conditions, as can ongoing world conflicts that continue to spread. And physical conflicts are typically accompanied by a cyber component, as demonstrated by recent attacks on municipal water systems perpetrated by alleged Iranian-backed cyber groups targeting use of Israeli-sourced control systems.

So, how should organizations adjust cybersecurity initiatives to address continued economic uncertainty in 2024? First and foremost, cybersecurity investments will continue to need proper justification based on empirical data. Financial decision-makers will look favorably on program and control improvements that assert quantifiable bottom-line impact, such as prevention of costly production down-time or potential negative adjustments to stock price and cost-of-borrowing. And to the extent that it’s possible, investments need to demonstrate positive returns for the organization, such as improved customer confidence and satisfaction or greater market share. For example, customers may be reluctant to continue doing business with an organization that does not value their data privacy or impedes their ability to procure goods in a just-in-time approach. Organizations that consistently demonstrate their commitment to cybersecurity may see the lion’s share of new business as “cybersecurity as a competitive advantage” takes hold, especially in light of increasingly newsworthy disclosures of material breaches. Cultivating a reliable cyber risk quantification (CRQ) process will be front-and-center, allowing organizations not only to evaluate potential threats but to demonstrate quantified value to the bottom-line. CISOs will need to lead the organizational effort to institutionalize a CRQ process that unites decision-makers in their consideration of cybersecurity value.

CRQ will also help the organization to identify high-impact, low-investment opportunities that substantially improve their cybersecurity programs. In 2024, CISOs will need to get serious about performance metrics to support program improvement and decision-making. Asserting the use of a cybersecurity framework or touting a particular cybersecurity maturity score will no longer be an acceptable substitute for actual performance. For example, cybersecurity processes that are not performing as designed-such as a failure to properly decommission privileged credentials in a timely manner-can be observed, measured, and adjusted to reduce or eliminate potentially costly cyber risk. This may only require small investments in tweaking processes or controls, with huge potential payoff.

2024 will also elevate cybersecurity as a core organizational function. The central role of the CISO as a trusted advisor and fiduciary party will increase, spurred-on by recent SEC rulings and the realization that cybersecurity is now a core pillar of enterprise risk management. As always, CISOs will need to continue the activities that helped them navigate stressful economic waters in 2023. A continued emphasis on technology rationalization will prevail, forcing a truthful examination of technical debt, shelfware, and the usefulness of existing tools and methods. Continued alignment and convergence of IT and cybersecurity missions is important to achieving technology rationalization, so building bridges between these teams-and operational technology teams, if applicable-will be vital as well. Along these lines, 2024 may usher in the need to formally detach cybersecurity budgets from IT budgets. Cybersecurity is a multi-disciplinary activity that deserves its own strategic planning and budgeting activity, particularly as the CISO’s role with senior management and boardrooms is elevated. And CRQ is better informed by financial inputs that directly and specifically originate with CISOs and cybersecurity personnel.

However, moving into the new year, warning signs abound for small and medium-sized businesses with respect to cybersecurity. These organizations tend to underspend on cybersecurity staff and controls, and therefore become an easy-and desirable-target for hackers, particularly ransomware. They also tend to have higher engagement with third parties, particularly on outsourced IT and cybersecurity services, and therefore are highly exposed to inherited cyber risk. Coupled with the fact that there is a critical shortage of cybersecurity professionals overall-with an estimated 700,000 job vacancies-small and medium-sized businesses are at a disadvantage in competing for skilled labor, particularly when funded by taxpayers as is common with municipal services.

Finally, the emerging impact of artificial intelligence (AI) on both advancements in cybersecurity as well as potential energizing of threats will likely start to have an impact in 2024. AI is already a foundational engine in many of the tools used by cybersecurity professionals on a daily basis, but its role as a disruptor technology is in its infancy. 2024 will see exponential use of AI technology to improve decision-making, if only because of its ability to help cybersecurity professionals synthesize large amounts of data with little effort-data that may be invaluable to program strategy and implementation.

Indeed, 2024 is setting up to be an interesting, if not challenging, environment in which to be a CISO. Navigating economic conditions will continue to require agility, strategy, and collaboration. But no matter how economic conditions play out, one enduring truth remains: attackers are more resilient to economic uncertainty-and their mission will continue unabated. What matters most is the durability and resilience of your cybersecurity program as economic conditions change.

##

ABOUT THE AUTHOR

Richard Caralli is a senior cybersecurity advisor at Axio with significant executive-level experience in developing and leading cybersecurity and information technology organizations in academia, government, and industry. Caralli has 17 years of leadership experience in internal audit, cybersecurity, and IT in the natural gas industry, retiring in 2020 as the Senior Director -Cybersecurity at EQT/Equitrans. Previously, Caralli was the Technical Director of the Risk and Resilience program at Carnegie Mellon’s Software Engineering Institute CERT Program, where he was the lead researcher and author of the CERT Resilience Management Model (CERT-RMM), providing a foundation for the Department of Energy’s Cybersecurity Capability Maturity Model (C2M2) and the emerging Cybersecurity Maturity Model Certification (CMMC). During his 15-year tenure at Carnegie Mellon, Caralli was also involved in creating educational and internship programs for Master’s degree and continuing education students at the Heinz College.